r/Splunk
CIM normalization on ES Splunk Cloud Classic - Use TA vs. staying in-app?
Working on a large Splunk Cloud engagement (Classic Experience, ES on the premium search head) and want a sanity check on a design decision.
Normally I'd go the Add-on Builder route for CIM tag/eventtype work. Problem is Classic doesn't support self-service app install on premium search heads, so every TA push to the ES SH means a Support ticket as I understand it. This would slow us down and add a lot of overhead.
Right now we're building tags/eventtypes directly in the ES app via Settings (globally shared).
Curious how others have handled this:
- Anyone doing continuous TA pushes via Support tickets and it's not as painful as it sounds?
- Has an ES upgrade ever clobbered custom local tags/eventtypes living in the ES app, or is that risk overstated?
- Better middle ground I'm missing?
Thanks!
Course Recommendations
Hi Guys! I really want to learn splunk to help me land a SOC analyst role. What are some course recommendations on youtube or udemy that helped y'all pass the power user certification or just gain some hands on experience for beginners.
Splunk Add-on for Microsoft Cloud Services
I'm searching for some advice for the installation of Splunk Add-on for Microsoft Cloud Services in a distributed environment (SH-Cluster/IDX-Cluser/SHC-Deployer/Cluster-Master) - NO Heavy Forwarder!
The documentation of the addon confuses me:
"As a best practice, turn off add-on visibility on your search heads to prevent data duplication errors that can result from running inputs on your search heads instead of or in addition to your data collection node."
From this I understand that a HF is needed, but the table says its not required....
The addon gets events from an Event-Hub with API requests - so when I'm running it on the Search-Heads I have to make sure they are using a proper outputs.conf, pointing to the indexer cluster ?
Anyone heaving experience ?
Explorando splunk
Nuevo en ciberseguridad y splunk ha sido una de las cosas que más me ha llamado la atención. Saber identificar amenazas leyendo estos logos es lo más interesante de un SOC
What should a Splunk engineer with 3 years of experience know?
Hey guys, I've been working with Splunk for the last 3 years (splunk enterprise, ES), but I don't feel like I know Splunk as well as someone with 3 years of experience probably should.
For the seniors here who have been working with Splunk for a while, what are some topics or concepts you would expect someone with ~3 years of experience to know?
I'd really appreciate it if you could share some areas I should be focusing on or learning. Thanks!
Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk Lantern
Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for Security, Observability, Industries, AI, and Cisco. We also host valuable data source and data type libraries, Getting Started Guides for all major products, tips on managing data more effectively within the Splunk platform, and many more expert-written guides to help you achieve more with Splunk.
This month, we're spotlighting a comprehensive new series on working with threat intelligence in Splunk Enterprise Security 8.5. We're also diving into the major agentic upgrade to Splunk AI Assistant v2, and exploring how the new Cisco Security Cloud add-on can transform your SOC operations. Plus, we've got a range of other new articles covering platform performance, data forwarding, and more. Let's get into it!
Mastering Threat Intelligence in Splunk Enterprise Security 8.5
Threat intelligence is a cornerstone of effective security operations, but it isn't "plug and play". Intel arrives in varied formats that must be parsed, normalized, matched, and enriched before it becomes truly useful. This month, we've published a comprehensive article series that gives detection engineers, admins, and data architects an end-to-end, hands-on walkthrough of how threat intel works in Splunk Enterprise Security 8.5.
The series opens with an overview article, Working with threat intelligence sources in Enterprise Security 8.5, which explains the two primary pillars of ES threat intelligence: the native Threat Intelligence Framework (TIF) and the cloud-based Splunk Threat Intelligence Management (TIM Cloud). It's the perfect starting point for understanding how these components relate to one another before diving into the technical detail.
From there, three focused articles go into the details:
- Configuring native threat intelligence sources in Enterprise Security 8.5 shows you how to activate a prepackaged source (using PhishTank as an example), how TIF parses and routes data, and how to add a custom feed, using Malware Bazaar as an example.
- Detecting threats and enriching investigations with native threat intelligence in Enterprise Securit... picks up the story, unpacking how threat matching searches surface IOC matches, how findings become alerts through detections like Threat Activity Detected, and how to capture IOCs as observables in the Investigation Intelligence tab.
- Finally, Enriching threat intelligence with cloud-based sources in Enterprise Security 8.5 covers TIM Cloud—showing how it stores cloud intel, how to search that intel, and how normalized threat scoring drives the Priority Score that analysts see in investigations.
Whether you're setting up threat intel for the first time or looking to deepen your understanding of how ES surfaces and enriches threats, this series is an invaluable reference. Which threat intelligence topics would you like us to cover next? Drop us a comment below!
Getting More from Splunk AI Assistant v2 with Agent Mode and Semantic Search
Splunk AI Assistant has evolved. Formerly known as the Splunk AI Assistant for SPL, the new 2.0 release drops "for SPL" because it's no longer just a tool for writing queries. Our new article, Getting more from Splunk AI Assistant v2 with Agent Mode and Semantic Search, explores how this agentic upgrade helps your team complete complex, multi-step tasks from a single prompt.
The article walks through the standout new capabilities. Agent Mode lets the Assistant act on your behalf—running event scans, discovering existing dashboards and alerts, running searches, and summarizing findings—all with human-in-the-loop approval at every step, and always scoped by the user's existing permissions. Semantic Search maps your natural language queries to conceptually related terms, so asking "what data do I have about failed logins" surfaces relevant source types and existing content even if those exact words don't appear in your metadata. And Teach AI lets admins provide custom organizational knowledge like naming conventions, data catalogs, or approved sources so the Assistant molds to your specific environment.
To bring it all to life, the article includes a full SOC investigation walkthrough showing how Agent Mode decomposes a prompt like "find all failed login activities in the last 24 hours and summarize what you find" into discrete, approvable steps, plus instructions for rebuilding the demo yourself. Let us know in the comments below how you're putting AI Assistant v2 to work!
Improving Your SOC Operations with Cisco Security Cloud Integrations
Comprehensive security is great until managing the software and alerts across all your tools becomes overwhelming. Our new article, Improving your SOC operations with Cisco Security Cloud integrations, shows how the Splunk platform can bring data and alerts from fourteen different Cisco security applications together in one place, using the Cisco Security Cloud add-on rather than a separate Splunkbase add-on for each tool.
Beyond simplifying data ingestion, the Cisco Security Cloud add-on automatically maps incoming data to the Splunk Common Information Model, so disparate fields and values can be easily correlated and enriched for greater SOC efficiency.
The article walks through key use cases for a range of Cisco applications, including:
- Cisco XDR
- Secure Network Analytics
- Duo
- AI Defense
- Secure Email Threat Defense
- Multicloud Defense
- Secure Firewall, and more.
If you're running Cisco security tools alongside Splunk software, this is essential reading. How are you combining Cisco and Splunk tools in your SOC? Share your setup in the comments!
What Else is New?
Beyond our featured topics, we've published several more articles covering platform performance, data management, and network automation:
- Understanding file monitoring on Splunk forwarders: The basics of fishbucket and CRC
- Forwarding OCI Streaming to Splunk with Splunk OpenTelemetry Collector for Kafka
- Enhancing network automation with event-driven architecture
- Comparing search head performance gains after upgrading a low-utilization cluster
We hope these expert-written resources help you get even more value out of your Splunk deployment. Thanks for reading!
Multiple Splunk Cloud Instances vs Rules
Im at a job that handles multiple instances of splunk cloud enterprise security per each tenant. And we need a solution to syncronize or ship out detection rules and versioning from 1 splunk cloud to the others... we were thinking to develop a local tool that connects all API keys from each splunk cloud instance and handle actions from there to push(post) new rules and also update or modify current ones? Any else had encountered this type of scenario, any solutions on how to achieve this? Thankyou